Re: LastPass Vault Breached via Employee's Home Computer

[email protected] Wed, 01 Mar 2023 13:22:24 -0600
Newsgroups alt.privacy.anon-server,alt.computer.security
Organization A noiseless patient Spider
Message-ID <[email protected]>
On Wed,  1 Mar 2023 06:21:02 +0000 (GMT), The Stuff of Legend
<Use-Author-Supplied-Address-Header@[127.1]> wrote:

>On Tue, 28 Feb 2023 20:04:06 -0600, [email protected] said in 
>Message-ID: <[email protected]>: 
>
>> https://pjmedia.com/news-and-politics/gregbyrnes/2023/02/28/lastpass-vault-breached-via-employees-home-computer-giving-keys-to-the-kingdom-to-hackers-n1674308
>> 
>> "Millions of LastPass users may be at risk after a major breach of the
>> home computer of one of their top employees. This employee was only
>> one of four people in the company with access to their corporate
>> vault. The breach may have come through a home Plex media account,
>> according to Ars Technica*, and appears to have been perpetrated by
>> the same hackers who breached LastPass security on a smaller scale
>> last August. At about the same time, Plex’s security was also
>> breached."
>> 
>> *https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/
>> 
>> This is wjy I don't use password mangagers.  I keep my
>> passwords/phrases in a PGP file on my comp. 
>> Yeah, I gotta copy paste after opening the PGP, but it is safer than
>> using password "protector" dumbware like LastPass.
>
>The problem isn't password managers, per-se -- the problem is relying on a cloud-
>based provider like LastPass. BTW, using PGP is a *great* idea for protecting 
>your passwords and other confidential data, especially if you use symmetric 
>encryption to do so, using a Dicewareâ„¢ passphrase. 
>
>Back in the day, in a moment of madness, I seriously considered using LastPass, 
>but ultimately what turned me off, and made me change my mind, was the cloud-
>based nature of the service. I just don't feel comfortable storing /any/ data in 
>the cloud, regardless of its' sensitivity. 
>

What gets me about this "cloud' stuff is that the "cloud" is just
another server somewhere else on earth just like any other server.

I guess there are enough fools who believe that "cloud" actually means
the server is somewhere up in an actual cloud, nearer to God, and God
is keeping it secure.

Jeesh!